<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sekiur My Thoughts &#187; spyware</title>
	<atom:link href="http://blog.sekiur.com/tag/spyware/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sekiur.com</link>
	<description>VoIP, Mobility, Security, Open Source, Science, Politics, and Technology.</description>
	<lastBuildDate>Wed, 24 Aug 2011 19:46:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Its the FMI&#8217;s Turn at Being Hacked</title>
		<link>http://blog.sekiur.com/2008/11/its-the-fmis-turn-at-being-hacked/</link>
		<comments>http://blog.sekiur.com/2008/11/its-the-fmis-turn-at-being-hacked/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 05:41:58 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[fox news]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[imf]]></category>
		<category><![CDATA[incident]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=562</guid>
		<description><![CDATA[<p>Within weeks of the World Bank&#8217;s story breaking about its computer systems being breached by hackers, Fox News has reported here that Cyber-Hackers have broken into the IMF computer system.</p> <p>The International Monetary Fund (IMF) is an <a title="International organization" href="http://en.wikipedia.org/wiki/International_organization">international organization</a> that oversees the <a title="Global financial system" href="http://en.wikipedia.org/wiki/Global_financial_system">global financial system</a> by following the [...]]]></description>
			<content:encoded><![CDATA[<p>Within weeks of the World Bank&#8217;s story breaking about its computer systems being breached by hackers, Fox News has reported here that Cyber-Hackers have broken into the IMF computer system.</p>
<blockquote><p>The <strong>International Monetary Fund</strong> (<strong>IMF</strong>) is an <a title="International organization" href="http://en.wikipedia.org/wiki/International_organization">international organization</a> that oversees the <a title="Global financial system" href="http://en.wikipedia.org/wiki/Global_financial_system">global financial system</a> by following the <a class="mw-redirect" title="Macroeconomic policies" href="http://en.wikipedia.org/wiki/Macroeconomic_policies">macroeconomic policies</a> of its member countries, in particular those with an impact on <a title="Exchange rate" href="http://en.wikipedia.org/wiki/Exchange_rate">exchange rates</a> and the <a title="Balance of payments" href="http://en.wikipedia.org/wiki/Balance_of_payments">balance of payments</a>. It also offers financial and technical assistance to its members, making it an international <a title="Lender of last resort" href="http://en.wikipedia.org/wiki/Lender_of_last_resort">lender of last resort</a>. Its headquarters are located in <a title="Washington, D.C." href="http://en.wikipedia.org/wiki/Washington,_D.C.">Washington, D.C.</a>, <a title="United States" href="http://en.wikipedia.org/wiki/United_States">USA</a>.</p></blockquote>
<p>The IMF of course absolutely denies that the event took place. <span id="intelliTXT">The spyware discoveries came at a particularly sensitive time for the international bailout institution, which along with the World Bank is expected to play a central role in trying to combat global financial turmoil.</span></p>
<p>This is too much of a coincidence in my opinion. Any information taken by the attackers will likely be used as leverage to blackmail the institutions rather than being made public to embarass them.</p>
<blockquote><p><span id="intelliTXT">In fact, the computer assaults on the World Bank and the IMF are only part of a rash of sensitive cyber-burglaries that even reached into the U.S. presidential campaign. Both London&#8217;s Financial Times and Newsweek recently reported that the computer network of the White House, and the Obama and McCain campaigns, were seriously breached.</span></p>
<p>The Pentagon claims the Chinese army has established units to develop viruses to attack enemy computer systems. Chinese hackers penetrated the Pentagon last year, in an attack that obtained e-mails from the system serving Defense Secretary Robert Gates.</p>
<p>Despite vigorous Chinese denials, &#8220;everyone in the intelligence community knows that China is the biggest player in cyber espionage,&#8221; says John Tkacik, a former head of China intelligence for the U.S. State Department. Tkacik told FOX News that later this month, President-elect Obama will be presented with a new top-secret National Intelligence Estimate (NIE) report that &#8220;will cause the scales to drop from his eyes&#8221; regarding Chinese cyber-espionage.</p>
<p>&#8220;What the Chinese are particularly interested in at the IMF is what loans the IMF is likely to give to other countries,&#8221; says Nick Day, a former British intelligence officer who runs Diligence, a private investigative firm that does extensive work for many international corporations and institutions.</p>
<p>&#8220;The geopolitics of this is that essentially you&#8217;ve got a few countries in the world that are stacked on huge foreign capital reserves — Russia, China, Japan, the Middle East — and the rest of us are pretty much borrowers to those lenders.</p></blockquote>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2008/11/its-the-fmis-turn-at-being-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Worm Takes Advantage Of Microsoft Flaw</title>
		<link>http://blog.sekiur.com/2008/10/worm-takes-advantage-of-microsoft-flaw/</link>
		<comments>http://blog.sekiur.com/2008/10/worm-takes-advantage-of-microsoft-flaw/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 23:20:39 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[buffer overflow]]></category>
		<category><![CDATA[dropper]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[gimmiv]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[milw0rm]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=433</guid>
		<description><![CDATA[<p>Just as I had predicted it would happen, there are already reports that a worm exploiting the hole in the <a href="http://blog.sekiur.com/wp-content/uploads/2008/10/worm.png"></a>&#8220;Server Service&#8221; has been seen in the wild. Microsoft released yesterday a critical &#8220;out-of-band&#8221; patch (<a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_self">MS08-067</a>) release having known about the issue for a while.</p> <p><a href="http://www.milw0rm.com/" target="_self">Milw0rm</a>, an exploit tracking Internet [...]]]></description>
			<content:encoded><![CDATA[<p>Just as I had predicted it would happen, there are already reports that a worm exploiting the hole in the <a href="http://blog.sekiur.com/wp-content/uploads/2008/10/worm.png"><img class="alignright size-medium wp-image-434" title="worm" src="http://blog.sekiur.com/wp-content/uploads/2008/10/worm.png" alt="" width="266" height="300" /></a>&#8220;Server Service&#8221; has been seen in the wild. Microsoft released yesterday a critical &#8220;out-of-band&#8221; patch (<a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_self">MS08-067</a>) release having known about the issue for a while.</p>
<p><a href="http://www.milw0rm.com/" target="_self">Milw0rm</a>, an exploit tracking Internet site has posted the <a href="http://www.milw0rm.com/exploits/6824" target="_self">exploit code</a> required to overflow the stack. The code can be downloaded <a href="http://milw0rm.com/sploits/2008-ms08-067.zip" target="_self">here</a>.</p>
<p><a href="http://www.symantec.com" target="_self">Symantec</a> is tracking an exploit &#8220;Bloodhound.Exploit.212&#8243;, via Bugtraq ID <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-102323-4508-99&amp;tabid=1" target="_self">31874</a> using this vulnerability, but they report it is still not widespread. Other reports points to a certain file &#8220;n2.exe&#8221; being downloaded to compromise computers, as McAfee has been tracking <a href="http://vil.nai.com/vil/content/v_152892.htm" target="_self">here</a>.</p>
<p>The worm as already received several names including Gimmiv and Dropper. The guys over at Threat Expert Blog have a pretty detailed <a href="http://blog.threatexpert.com/2008/10/gimmiva-exploits-zero-day-vulnerability.html" target="_self">explanation</a> of how the code works and what it does.</p>
<blockquote><p>Both <a href="http://www.symantec.com" target="_self">Symantec</a> and <a href="http://www.mcafee.com" target="_self">McAfee</a> said Friday that they had seen only a very small number of attacks based on this exploit, but Symantec says that, starting Thursday evening, they found a 25 percent jump in network scans looking for potentially vulnerable machines. That could be a sign that more attacks are coming.</p></blockquote>
<p>It is not likely that large networks will have ports 139 and/or 445 open to the Internet and even most DSL/Cable modem router will not allow this kind of inbound traffic either, but I have no doubt this will cause a false sense of security among pseudo-system admins and as this worm evolves and becomes more sophisticated, it will transverse corporate perimeter firewall through malware and spyware and then spread within the network wreaking havoc.</p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2008/10/worm-takes-advantage-of-microsoft-flaw/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Swiss Army Knife for Your PC</title>
		<link>http://blog.sekiur.com/2008/09/the-swiss-army-knife-for-your-pc/</link>
		<comments>http://blog.sekiur.com/2008/09/the-swiss-army-knife-for-your-pc/#comments</comments>
		<pubDate>Mon, 15 Sep 2008 19:29:22 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=169</guid>
		<description><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2008/09/swiss-army-knife.jpg"></a>Great article at <a href="http://lifehacker.com/397792/five-best-windows-maintenance-tools" target="_self">Lifehacker</a> on Windows maintenance tools that anyone wanting to run a healthy PC should have installed.</p> <p>Apart from <a href="http://www.ccleaner.com/" target="_blank">CCleaner</a>, <a href="http://www.revouninstaller.com/" target="_blank">Revo Uninstaller</a>, <a href="http://www.auslogics.com/disk-defrag" target="_blank">Auslogic Disk Defrag</a>, and <a href="http://www.safer-networking.org/en/spybotsd/index.html" target="_blank">Spybot</a> &#8211; Search &#38; Destroy, I would also add some in case virus/malware/spyware removal is required. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2008/09/swiss-army-knife.jpg"><img class="alignleft size-thumbnail wp-image-170" title="swiss-army-knife" src="http://blog.sekiur.com/wp-content/uploads/2008/09/swiss-army-knife-150x150.jpg" alt="" width="150" height="150" /></a>Great article at <a href="http://lifehacker.com/397792/five-best-windows-maintenance-tools" target="_self">Lifehacker</a> on Windows maintenance tools that anyone wanting to run a healthy PC should have installed.</p>
<p>Apart from <a href="http://www.ccleaner.com/" target="_blank">CCleaner</a>, <a href="http://www.revouninstaller.com/" target="_blank">Revo Uninstaller</a>, <a href="http://www.auslogics.com/disk-defrag" target="_blank">Auslogic Disk Defrag</a>, and <a href="http://www.safer-networking.org/en/spybotsd/index.html" target="_blank">Spybot</a> &#8211; Search &amp; Destroy, I would also add some in case virus/malware/spyware removal is required. <a href="http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx" target="_blank">RootKitRevealer</a>, <a href="http://lavasoft.com/" target="_blank">Ad-Aware</a>, <a href="http://www.majorgeeks.com/ATF_Cleaner_d4949.html" target="_blank">ATF-Cleaner</a>, <a href="http://swandog46.geekstogo.com/" target="_blank">Avenger</a>, <a href="http://majorgeeks.com/download3155.html" target="_blank">HijackThis</a> and <a href="http://www.simplysup.com/" target="_blank">Trojan Remover</a>.</p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2008/09/the-swiss-army-knife-for-your-pc/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

